The numbers behind the minister's warning
On September 10, 2026, Communications Minister Fahmi Fadzil told the inaugural M360 ASEAN conference in Kuala Lumpur that 65,280 scam and illegal-gambling posts were still online despite takedown requests from the Malaysian Communications and Multimedia Commission (MCMC). According to The Vibes' report of the speech, MCMC sent platforms more than one million requests between January 1, 2025 and August 31, 2026. Platforms removed 935,416 items, a 93% compliance rate. The removals included 592,695 gambling posts and 227,486 scam posts, together about 88% of everything taken down.
Fahmi said platforms must be "more proactive, not merely remove" content. He also noted that sellers of prohibited goods, such as fentanyl vapes, use coded language to avoid detection.
The strongest case for the minister
The regulator's argument deserves a fair statement. Scams and illegal gambling are not contested speech. They are fraud and unlicensed commerce, and the victims are real. MCMC's own Online Safety Act 2025 page cites RM2.7 billion in online scam losses and 67,735 scam cases reported between January and November 2025. A 93% compliance rate still leaves tens of thousands of live posts. Notice-and-takedown is also inherently reactive: a regulator that must find each post, file each request and wait for each response is always behind sellers who repost under new accounts. If a platform can reliably detect a pattern, regulators will say it should act before a citizen is defrauded.
What the data actually shows
The same figures support a less alarming reading. A 93% rate is high by any international standard for a system that has no statutory removal clock in the numbers cited. The remaining 65,280 posts are a small fraction of more than a million requests. Some are likely in transit, disputed, or on services with weak local presence. The minister's statement does not say how many remain because of platform refusal, how many are recent requests still being processed, and how many are re-uploads. Without that breakdown, "proactive" is a slogan, not a diagnosis.
The legal toolkit has also just been strengthened. The Communications and Multimedia (Amendment) Act 2025 [Act A1743], in force since February 11, 2025, amended section 233 of the Communications and Multimedia Act 1998. According to Skrine's analysis, it replaced "offensive" with "grossly offensive", added transmission with intent to commit fraud or dishonesty, and raised the maximum fine from RM50,000 to RM500,000 with up to two years' imprisonment. Those changes aim at the sellers, not the intermediaries, which is the right target.
Where "proactive" gets risky
The Online Safety Act 2025 [Act 866] adds a second layer. The Risk Mitigation Code and Child Protection Code took effect on June 1, 2026. Allen & Gledhill's summary says they require content moderation and detection-and-removal systems, with penalties of up to RM10 million. It also notes that they are outcome-based and do not set specific automation standards. That flexibility is valuable and should be preserved.
The danger is in how the minister's phrase is later translated into practice. Three problems follow if "proactive" hardens into an expectation of automated, pre-emptive removal:
- Coded language cuts both ways. If sellers use euphemisms, classifiers trained to catch euphemisms will also catch jokes, slang, harm-reduction advice and journalism. Error rates that are tolerable for spam become speech problems when applied to ambiguous categories.
- Compliance is measured by volume. A regulator that counts removals rewards over-removal. The 935,416 figure tells us how much was taken down, not how much of it was correctly taken down. No appeal or error rate is reported.
- Scope creep. The Act's harmful-content categories extend beyond fraud to obscene content, harassment and hate speech, according to MCMC's own page. Detection tooling built for scams will be pointed at those categories next, where the lines are far less clear.
India offers a cautionary parallel, with proposals such as an ISP-level AI ban on obscene content being criticised by MediaNama as unworkable. Mandating filtering at the wrong layer produces false positives and little else.
A proportionate path
Malaysia can close the gap without moving to general monitoring:
- Publish the residual. MCMC should report how many of the 65,280 are pending, refused or reposted, by platform and by category. That would turn a headline into a compliance map.
- Target repeat offenders. The Risk Mitigation Code's repeat-offender policies, plus section 233's higher penalties, are better aimed at the small number of accounts producing most of the fraud than at every user's speech.
- Use hash and account-level matching for re-uploads. Matching previously removed content is narrow, auditable and avoids guessing intent from vocabulary.
- Report error rates. Platforms and MCMC should disclose reversals and appeals alongside removals, so that "93%" is paired with an accuracy number.
- Keep human review for coded-language cases. Ambiguous terms should trigger escalation to trained reviewers, not automatic deletion.
Conclusion
A 93% compliance rate is evidence that the existing notice-and-takedown relationship functions. The remaining 65,280 posts are a reason for better data and sharper enforcement against offenders, and Fahmi's call for platforms to be more proactive should be read as an invitation to build targeted tools. It should not become a mandate for the unaudited automated filtering that would sweep up lawful speech along with fraud.